Enterasys Networks 9034385 Plumbing Product User Manual


 
Enterasys NAC Design Guide 5-1
5
Design Procedures
ThischapterdescribesthedesignproceduresforEnterasysNACdeploymentonanenterprise
network.ThefirstsectiondiscussesproceduresforbothoutofbandandinlineNAC
deployments.Thesecondsectiondiscussesproceduresfordeploymentsimplementing
assessment.Subsequentsectionspresentdesignstepsrelatingspecificallytooutofband
deploymentsusingthe
NACGatewayandinlinedeploymentsusingtheNACController.
Procedures for Out-of-Band and Inline NAC
Thissectionpresentsdesignproceduresthatareapplicable tobothoutofbandandinlineNAC
deployments.
1. Identify Required NetSight Applications
AsdiscussedinNetSightManagementonpage 1 9,theEnterasysNACsolutionrequiresthe
installationoftwoapplicationsfromtheNetSightmanagementsoftwaresuite.NetSightNAC
ManagerisrequiredtocentrallymanagetheNACControllerandNACGatewayapplianceson
thenetwork.BecauseNACManagerisapluginapplicationto
NetSightConsole,itisnecessaryto
haveNetSightConsoleinstalledonaserverwithNACManager.NetSightConsoleisusedto
monitorthehealthandstatusofdevicesonthenetwork,includingtheaccesslayerswitchesand
theNACappliances.
Inaddition,NetSightPolicyManagerisrequiredforinlineNACdeployments.
PolicyManageris
usedtocentrallydefineanddistributepoliciestoallNACControllersonthenetwork.
ForoutofbandNACdeploymentsthat includeEnterasyspolicy enabledswitchesinthe
intelligentedge,policiesarespecifiedinNACManagerthatauthorizeconnectingendsystems
withaparticularlevelofnetworkaccess.
Policiesare centrallydefinedanddistributedtothose
EnterasysswitchesusingPolicyManager.WithPolicyManager,policyrolesareeasilydefined
andenforcedtoallEnterasysswitchesintheentireintelligentedgeofthenetwork,fromone
centrallocation.
For information about... Refer to page...
Procedures for Out-of-Band and Inline NAC 5-1
Assessment Design Procedures 5-17
Out-of-Band NAC Design Procedures 5-19
Inline NAC Design Procedures 5-28
Additional Considerations 5-33